Mustang Panda (Hive0154) rolled out SnakeDisk (USB worm) + Toneshell9/Yokai backdoor to target air-gapped networks (geo-targeted to Thailand). Indicators: hidden SYSTEM/HIDDEN dirs on USB, robocopy/SHFileOperation usage, payloads reconstructed in C:\Users\Public\, scheduled tasks for persistence. Immediate mitigations: enforce approved read-only media, disable autorun, monitor WM_DEVICECHANGE/IOCTL, block DLL sideloading, and scan media in isolated sandboxes.

Follow @technadu for IOCs & response playbooks.

#MustangPanda #USBWorm #AirGapSecurity #ThreatIntel #EDR #IR #InfoSec #Malware

#USBworm unleashed by Russian state #hackers spreads worldwide | Ars Technica

#LitterDrifter 's means of self-propagation are simple. So why is it spreading so widely?
#usb #worm #russia

https://arstechnica.com/security/2023/11/normally-targeting-ukraine-russian-state-hackers-spread-usb-worm-worldwide/

USB worm unleashed by Russian state hackers spreads worldwide

LitterDrifter's means of self-propagation are simple. So why is it spreading so widely?

Ars Technica

A strange USB worm created by Russian hackers,
Has spread far since its latest attackers.
The method's quite simple,
It's spread with a stumble.

#usbworm #russianhackers #cybersecurity #poetry

https://arstechnica.com/security/2023/11/normally-targeting-ukraine-russian-state-hackers-spread-usb-worm-worldwide/

USB worm unleashed by Russian state hackers spreads worldwide

LitterDrifter's means of self-propagation are simple. So why is it spreading so widely?

Ars Technica
Transparent Tribe Mounts Ongoing Spy Campaign on Military, Government - The group has added a management console and a USB worming function to its main malware, Crimson R... https://threatpost.com/transparent-tribe-ongoing-spy-campaign-military-government/158515/ #transparenttribe #vulnerabilities #militarytargets #cyberespionage #spearphishing #cyberattacks #spycampaign #government #crimsonrat #datatheft #malware #usbworm #apt
Transparent Tribe Mounts Ongoing Spy Campaign on Military, Government

The group has added a management console and a USB worming function to its main malware, Crimson RAT.

Threatpost - English - Global - threatpost.com